Compare commits
16 Commits
Author | SHA1 | Date | |
---|---|---|---|
6004f6aeb4
|
|||
3ffcf262e5
|
|||
550b5ff28a
|
|||
302f4df307
|
|||
b8f4a3c46f
|
|||
1cee3b5dae
|
|||
0d28c61c0f
|
|||
7fefc75d64
|
|||
e0398bd8fb
|
|||
5ff83f3af7
|
|||
e85858d342
|
|||
6811740835 | |||
86ab9808d8 | |||
117a74989e
|
|||
b91a7ae0fc
|
|||
e3043c5646
|
1
.gitignore
vendored
1
.gitignore
vendored
@ -4,4 +4,5 @@ defs/
|
|||||||
__pycache__/
|
__pycache__/
|
||||||
.*.swp
|
.*.swp
|
||||||
tmp/
|
tmp/
|
||||||
|
locallibs
|
||||||
|
|
||||||
|
@ -1,6 +1,6 @@
|
|||||||
stages:
|
stages:
|
||||||
- generate-api-clients
|
- generate-api-clients
|
||||||
- dockerize
|
- build
|
||||||
|
|
||||||
variables:
|
variables:
|
||||||
REGISTRY: devnexus.krohne.com:18079/repository/docker-krohne
|
REGISTRY: devnexus.krohne.com:18079/repository/docker-krohne
|
||||||
@ -31,7 +31,7 @@ generate-dtrack-api:
|
|||||||
extends: .generate-api
|
extends: .generate-api
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- dtrack-api-client.tgz
|
- dependencytrack-client
|
||||||
expire_in: 1 week
|
expire_in: 1 week
|
||||||
script:
|
script:
|
||||||
- curl ${DTRACK_API_URL}/api/openapi.json > dependencytrack-openapi.json
|
- curl ${DTRACK_API_URL}/api/openapi.json > dependencytrack-openapi.json
|
||||||
@ -50,14 +50,13 @@ generate-dtrack-api:
|
|||||||
-o dependencytrack-client \
|
-o dependencytrack-client \
|
||||||
--package-name dependencytrack_api \
|
--package-name dependencytrack_api \
|
||||||
-t dependencytrack-openapi-custom-template
|
-t dependencytrack-openapi-custom-template
|
||||||
- tar -czvf dtrack-api-client.tgz dependencytrack-client
|
|
||||||
|
|
||||||
|
|
||||||
generate-defectdojo-api:
|
generate-defectdojo-api:
|
||||||
extends: .generate-api
|
extends: .generate-api
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- defectdojo-api-client.tgz
|
- defectdojo-client
|
||||||
expire_in: 1 week
|
expire_in: 1 week
|
||||||
script:
|
script:
|
||||||
- curl ${DEFECTDOJO_API_URL}/api/v2/oa3/schema/?format=json > defectdojo-openapi.json
|
- curl ${DEFECTDOJO_API_URL}/api/v2/oa3/schema/?format=json > defectdojo-openapi.json
|
||||||
@ -68,10 +67,9 @@ generate-defectdojo-api:
|
|||||||
-g python \
|
-g python \
|
||||||
-o defectdojo-client \
|
-o defectdojo-client \
|
||||||
--package-name defectdojo_api
|
--package-name defectdojo_api
|
||||||
- tar -czvf defectdojo-api-client.tgz defectdojo-client
|
|
||||||
|
|
||||||
dockerize:
|
dockerize:
|
||||||
stage: dockerize
|
stage: build
|
||||||
image: devnexus.krohne.com:18079/repository/docker-krohne/krohnedockerbash:0.5
|
image: devnexus.krohne.com:18079/repository/docker-krohne/krohnedockerbash:0.5
|
||||||
tags:
|
tags:
|
||||||
- linux
|
- linux
|
||||||
@ -80,8 +78,6 @@ dockerize:
|
|||||||
rules:
|
rules:
|
||||||
- if: '$CI_COMMIT_TAG'
|
- if: '$CI_COMMIT_TAG'
|
||||||
script:
|
script:
|
||||||
- tar -xzf defectdojo-api-client.tgz
|
|
||||||
- tar -xzf dtrack-api-client.tgz
|
|
||||||
- docker build --build-arg ADDITIONAL_CA_URL="$KROHNE_CA_URL"
|
- docker build --build-arg ADDITIONAL_CA_URL="$KROHNE_CA_URL"
|
||||||
--build-arg ADDITIONAL_CA_CHECKSUM=$KROHNE_CA_CHECKSUM
|
--build-arg ADDITIONAL_CA_CHECKSUM=$KROHNE_CA_CHECKSUM
|
||||||
--tag $IMAGE_NAME:latest
|
--tag $IMAGE_NAME:latest
|
||||||
@ -93,38 +89,29 @@ dockerize:
|
|||||||
- docker push $IMAGE_NAME:$CI_COMMIT_SHA
|
- docker push $IMAGE_NAME:$CI_COMMIT_SHA
|
||||||
- docker push $IMAGE_NAME:$CI_COMMIT_TAG
|
- docker push $IMAGE_NAME:$CI_COMMIT_TAG
|
||||||
|
|
||||||
|
build-windows-binary:
|
||||||
|
stage: build
|
||||||
|
tags:
|
||||||
|
- windows
|
||||||
|
- pwsh
|
||||||
|
- python3.13
|
||||||
|
rules:
|
||||||
|
- if: '$CI_COMMIT_TAG'
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- sbom-dt-dd.exe
|
||||||
|
script:
|
||||||
|
- |
|
||||||
|
cd src
|
||||||
|
mv ..\dependencytrack-client .
|
||||||
|
mv ..\defectdojo-client .
|
||||||
|
& 'C:\Program Files\Python313\python.exe' -m venv venv
|
||||||
|
.\venv\Scripts\pip.exe install --upgrade pip
|
||||||
|
.\venv\Scripts\pip.exe install -r requirements.txt
|
||||||
|
.\venv\Scripts\pip.exe install -r dependencytrack-client\requirements.txt
|
||||||
|
.\venv\Scripts\pip.exe install -r defectdojo-client\requirements.txt
|
||||||
|
.\venv\Scripts\pip.exe install pyinstaller
|
||||||
|
.\venv\Scripts\pyinstaller.exe --onefile --add-data "dependencytrack-client;dependencytrack-client" --add-data "defectdojo-client;defectdojo-client" sbom-dt-dd.py
|
||||||
|
mv dist\sbom-dt-dd.exe ..
|
||||||
|
|
||||||
|
|
||||||
#
|
|
||||||
# build:
|
|
||||||
# image: plugins/kaniko
|
|
||||||
# settings:
|
|
||||||
# repo: ${FORGE_NAME}/${CI_REPO}
|
|
||||||
# registry:
|
|
||||||
# from_secret: container_registry
|
|
||||||
# tags: latest,${CI_COMMIT_SHA},${CI_COMMIT_TAG}
|
|
||||||
# username:
|
|
||||||
# from_secret: container_registry_username
|
|
||||||
# password:
|
|
||||||
# from_secret: container_registry_password
|
|
||||||
# dockerfile: Dockerfile
|
|
||||||
# when:
|
|
||||||
# - event: [ push, tag ]
|
|
||||||
#
|
|
||||||
# build-for-quay:
|
|
||||||
# image: plugins/kaniko
|
|
||||||
# settings:
|
|
||||||
# repo: quay.io/wollud1969/${CI_REPO_NAME}
|
|
||||||
# registry: quay.io
|
|
||||||
# tags:
|
|
||||||
# - latest
|
|
||||||
# - ${CI_COMMIT_TAG}
|
|
||||||
# username:
|
|
||||||
# from_secret: quay_username
|
|
||||||
# password:
|
|
||||||
# from_secret: quay_password
|
|
||||||
# dockerfile: Dockerfile
|
|
||||||
# when:
|
|
||||||
# - event: [tag]
|
|
||||||
#
|
|
||||||
|
|
||||||
|
@ -41,14 +41,16 @@ steps:
|
|||||||
repo: ${FORGE_NAME}/${CI_REPO}
|
repo: ${FORGE_NAME}/${CI_REPO}
|
||||||
registry:
|
registry:
|
||||||
from_secret: container_registry
|
from_secret: container_registry
|
||||||
tags: latest,${CI_COMMIT_SHA},${CI_COMMIT_TAG}
|
tags:
|
||||||
|
- latest
|
||||||
|
- ${CI_COMMIT_SHA}
|
||||||
username:
|
username:
|
||||||
from_secret: container_registry_username
|
from_secret: container_registry_username
|
||||||
password:
|
password:
|
||||||
from_secret: container_registry_password
|
from_secret: container_registry_password
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
when:
|
when:
|
||||||
- event: [ push, tag ]
|
- event: [ push ]
|
||||||
|
|
||||||
build-for-quay:
|
build-for-quay:
|
||||||
image: plugins/kaniko
|
image: plugins/kaniko
|
||||||
|
10
src/ENV-krohne.asc
Normal file
10
src/ENV-krohne.asc
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
jA0ECQMC0qbzN9I9kGP/0sAlARybIFvSNy12iziCC4waAcAPBvvvVrutjyIYtaV1
|
||||||
|
z9WeoBv7TlHB9aKAgxj8LuSh44iDH6uz9FvZfYcZ2BpC9PQYr5IkIw9+iqq9hODM
|
||||||
|
P90Kr9CPazMR8BQUb+4iJjNlHKJL1HCYaFnSHdquzCD4KGqUkkRPPt4Oj/5baJVi
|
||||||
|
kfhU6bKuM6rarcVL0ebSbc2jUIEaugXhnvEWRTiAfOE8v6o7CneoK5hdMbhVA1iC
|
||||||
|
j3sVIcCWgfgMOGDfL2P8DCr7GsGoOxMXvfsPZZL1BRNIf8WXWGpml/TA5Q1vw8TM
|
||||||
|
z8l6SIHklQ==
|
||||||
|
=T8wW
|
||||||
|
-----END PGP MESSAGE-----
|
5
src/ENV-python
Normal file
5
src/ENV-python
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
export PYTHONPATH=./locallibs/defectdojo-client:./locallibs/dependencytrack-client
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
@ -9,6 +9,7 @@ from cyclonedx.model.bom import Bom
|
|||||||
from cyclonedx.model.component import Component, ComponentType
|
from cyclonedx.model.component import Component, ComponentType
|
||||||
from cyclonedx.model.contact import OrganizationalEntity
|
from cyclonedx.model.contact import OrganizationalEntity
|
||||||
from cyclonedx.model import XsUri
|
from cyclonedx.model import XsUri
|
||||||
|
from cyclonedx.model import ExternalReference
|
||||||
from cyclonedx.output.json import JsonV1Dot5
|
from cyclonedx.output.json import JsonV1Dot5
|
||||||
|
|
||||||
class MyLocalConverterException(Exception): pass
|
class MyLocalConverterException(Exception): pass
|
||||||
@ -54,7 +55,9 @@ def minimalSbomFormatConverter(minimalSbom, classifier):
|
|||||||
minimalSbomObject = yaml.safe_load(minimalSbom)
|
minimalSbomObject = yaml.safe_load(minimalSbom)
|
||||||
logger.debug(f"{minimalSbomObject=}")
|
logger.debug(f"{minimalSbomObject=}")
|
||||||
|
|
||||||
bom = Bom()
|
bom = Bom(
|
||||||
|
version=minimalSbomObject['sbomVersion']
|
||||||
|
)
|
||||||
bom.metadata.tools.components.add(cdx_lib_component())
|
bom.metadata.tools.components.add(cdx_lib_component())
|
||||||
bom.metadata.tools.components.add(Component(
|
bom.metadata.tools.components.add(Component(
|
||||||
name='sbom-dt-dd',
|
name='sbom-dt-dd',
|
||||||
@ -63,7 +66,8 @@ def minimalSbomFormatConverter(minimalSbom, classifier):
|
|||||||
|
|
||||||
bom.metadata.component = root_component = Component(
|
bom.metadata.component = root_component = Component(
|
||||||
name=minimalSbomObject['product'],
|
name=minimalSbomObject['product'],
|
||||||
type=__converterClassifierToComponentType(classifier),
|
type=__converterClassifierToComponentType(minimalSbomObject['classifier']),
|
||||||
|
description=minimalSbomObject['description'],
|
||||||
version=minimalSbomObject['version'],
|
version=minimalSbomObject['version'],
|
||||||
licenses=[lc_factory.make_from_string(minimalSbomObject['license'])],
|
licenses=[lc_factory.make_from_string(minimalSbomObject['license'])],
|
||||||
supplier=OrganizationalEntity(
|
supplier=OrganizationalEntity(
|
||||||
@ -73,6 +77,21 @@ def minimalSbomFormatConverter(minimalSbom, classifier):
|
|||||||
bom_ref = f"urn:uuid:{uuid.uuid4()}"
|
bom_ref = f"urn:uuid:{uuid.uuid4()}"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
component = Component(
|
||||||
|
type=__converterClassifierToComponentType(minimalSbomObject['classifier']),
|
||||||
|
name=f"{minimalSbomObject['supplier']['name']}´s own code",
|
||||||
|
version=minimalSbomObject['version'],
|
||||||
|
licenses=[lc_factory.make_from_string(minimalSbomObject['license'])],
|
||||||
|
supplier=OrganizationalEntity(
|
||||||
|
name=minimalSbomObject['supplier']['name'],
|
||||||
|
urls=[XsUri(minimalSbomObject['supplier']['url'])]
|
||||||
|
),
|
||||||
|
bom_ref = f"urn:uuid:{uuid.uuid4()}"
|
||||||
|
)
|
||||||
|
bom.components.add(component)
|
||||||
|
bom.register_dependency(root_component, [component])
|
||||||
|
|
||||||
|
|
||||||
for minimalComponentDescription in minimalSbomObject['components']:
|
for minimalComponentDescription in minimalSbomObject['components']:
|
||||||
component = Component(
|
component = Component(
|
||||||
type=ComponentType.LIBRARY,
|
type=ComponentType.LIBRARY,
|
||||||
@ -91,6 +110,8 @@ def minimalSbomFormatConverter(minimalSbom, classifier):
|
|||||||
outputSbom = JsonV1Dot5(bom).output_as_string(indent=2)
|
outputSbom = JsonV1Dot5(bom).output_as_string(indent=2)
|
||||||
logger.info(outputSbom)
|
logger.info(outputSbom)
|
||||||
|
|
||||||
|
with open('/tmp/bom.json', 'w') as f:
|
||||||
|
f.write(outputSbom)
|
||||||
|
|
||||||
raise Exception("Conversion aborted")
|
return (outputSbom, minimalSbomObject['product'], minimalSbomObject['version'], minimalSbomObject['classifier'], minimalSbomObject['description'])
|
||||||
|
|
||||||
|
47
src/prepare-local-env.sh
Executable file
47
src/prepare-local-env.sh
Executable file
@ -0,0 +1,47 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
. ./ENV
|
||||||
|
|
||||||
|
LOCALLBIS=./locallibs
|
||||||
|
OPENAPI_GENERATOR=openapitools/openapi-generator-cli:v7.12.0
|
||||||
|
|
||||||
|
mkdir $LOCALLBIS && cd $LOCALLBIS
|
||||||
|
|
||||||
|
# --- DependencyTrack Client Library -----------------------------------------------------
|
||||||
|
curl ${DTRACK_API_URL}/api/openapi.json >dependencytrack-openapi.json
|
||||||
|
|
||||||
|
docker run -v $PWD:/work -u $UID $OPENAPI_GENERATOR \
|
||||||
|
author template \
|
||||||
|
-g python \
|
||||||
|
-o /work/dependencytrack-openapi-custom-template
|
||||||
|
|
||||||
|
sed -i -e 's/import re/import regex as re/' dependencytrack-openapi-custom-template/model_anyof.mustache
|
||||||
|
sed -i -e 's/import re/import regex as re/' dependencytrack-openapi-custom-template/model_generic.mustache
|
||||||
|
|
||||||
|
docker run -v $PWD:/work -u $UID $OPENAPI_GENERATOR \
|
||||||
|
generate \
|
||||||
|
-i /work/dependencytrack-openapi.json \
|
||||||
|
-g python \
|
||||||
|
-o /work/dependencytrack-client \
|
||||||
|
--package-name dependencytrack_api \
|
||||||
|
-t /work/dependencytrack-openapi-custom-template
|
||||||
|
|
||||||
|
# --- Defectdojo Client Library ----------------------------------------------------------
|
||||||
|
curl ${DEFECTDOJO_URL}/api/v2/oa3/schema/?format=json >defectdojo-openapi.json
|
||||||
|
|
||||||
|
docker run -v $PWD:/work -u $UID $OPENAPI_GENERATOR \
|
||||||
|
generate \
|
||||||
|
-i /work/defectdojo-openapi.json \
|
||||||
|
-g python \
|
||||||
|
-o /work/defectdojo-client \
|
||||||
|
--package-name defectdojo_api
|
||||||
|
|
||||||
|
cd ..
|
||||||
|
|
||||||
|
python3 -m venv .venv
|
||||||
|
. .venv/bin/activate
|
||||||
|
pip install -r requirements.txt
|
||||||
|
pip install -r $LOCALLBIS/dependencytrack-client/requirements.txt
|
||||||
|
pip install -r $LOCALLBIS/defectdojo-client/requirements.txt
|
@ -4,11 +4,15 @@ import argparse
|
|||||||
import subprocess
|
import subprocess
|
||||||
import json
|
import json
|
||||||
|
|
||||||
import defectdojo_api
|
|
||||||
from defectdojo_api.rest import ApiException as DefectDojoApiException
|
|
||||||
import datetime
|
import datetime
|
||||||
from dateutil.relativedelta import relativedelta
|
from dateutil.relativedelta import relativedelta
|
||||||
|
|
||||||
|
sys.path.insert(0, os.path.join(os.path.dirname(__file__), 'defectdojo-client'))
|
||||||
|
sys.path.insert(0, os.path.join(os.path.dirname(__file__), 'dependencytrack-client'))
|
||||||
|
|
||||||
|
import defectdojo_api
|
||||||
|
from defectdojo_api.rest import ApiException as DefectDojoApiException
|
||||||
|
|
||||||
import dependencytrack_api
|
import dependencytrack_api
|
||||||
from dependencytrack_api.rest import ApiException as DependencyTrackApiException
|
from dependencytrack_api.rest import ApiException as DependencyTrackApiException
|
||||||
|
|
||||||
@ -63,13 +67,16 @@ except KeyError as e:
|
|||||||
parser = argparse.ArgumentParser(description='sbom-dt-dd glue logic')
|
parser = argparse.ArgumentParser(description='sbom-dt-dd glue logic')
|
||||||
parser.add_argument('--name', '-n',
|
parser.add_argument('--name', '-n',
|
||||||
help='Project Name',
|
help='Project Name',
|
||||||
required=True)
|
required=False,
|
||||||
|
default=''),
|
||||||
parser.add_argument('--version', '-v',
|
parser.add_argument('--version', '-v',
|
||||||
help='Project Version',
|
help='Project Version',
|
||||||
required=True)
|
required=False,
|
||||||
|
default='')
|
||||||
parser.add_argument('--description', '-d',
|
parser.add_argument('--description', '-d',
|
||||||
help='Project Description',
|
help='Project Description',
|
||||||
required=True)
|
required=False,
|
||||||
|
default='')
|
||||||
parser.add_argument('--type', '-t',
|
parser.add_argument('--type', '-t',
|
||||||
help='Product Type from DefectDojo',
|
help='Product Type from DefectDojo',
|
||||||
type=int,
|
type=int,
|
||||||
@ -78,7 +85,8 @@ parser.add_argument('--classifier', '-c',
|
|||||||
help='Project Classifier from DependencyTrack',
|
help='Project Classifier from DependencyTrack',
|
||||||
choices=['APPLICATION', 'FRAMEWORK', 'LIBRARY', 'CONTAINER', 'OPERATING_SYSTEM', 'DEVICE',
|
choices=['APPLICATION', 'FRAMEWORK', 'LIBRARY', 'CONTAINER', 'OPERATING_SYSTEM', 'DEVICE',
|
||||||
'FIRMWARE', 'FILE', 'PLATFORM', 'DEVICE_DRIVER', 'MACHINE_LEARNING_MODEL', 'DATA'],
|
'FIRMWARE', 'FILE', 'PLATFORM', 'DEVICE_DRIVER', 'MACHINE_LEARNING_MODEL', 'DATA'],
|
||||||
required=True)
|
required=False,
|
||||||
|
default='')
|
||||||
parser.add_argument('--uploadsbom', '-U',
|
parser.add_argument('--uploadsbom', '-U',
|
||||||
help='Upload a already existing SBOM instead of generating it. Give the SBOM file at -F instead of a target',
|
help='Upload a already existing SBOM instead of generating it. Give the SBOM file at -F instead of a target',
|
||||||
required=False,
|
required=False,
|
||||||
@ -91,9 +99,18 @@ parser.add_argument('--minimalsbomformat', '-K',
|
|||||||
help='SBOM file comes in dedicated minimal format and will be converted into cyclonedx before uploading',
|
help='SBOM file comes in dedicated minimal format and will be converted into cyclonedx before uploading',
|
||||||
action='store_true',
|
action='store_true',
|
||||||
default=False)
|
default=False)
|
||||||
|
parser.add_argument('--overwritemetadata', '-O',
|
||||||
|
help='Overwrite name, version, description and classifier with data from minimal SBOM',
|
||||||
|
action='store_true',
|
||||||
|
default=False)
|
||||||
parser.add_argument('--target', '-T',
|
parser.add_argument('--target', '-T',
|
||||||
help='Target to scan, either path name for sources or docker image tag',
|
help='Target to scan, either path name for sources or docker image tag',
|
||||||
required=False)
|
required=False)
|
||||||
|
parser.add_argument('--reimport', '-R',
|
||||||
|
help='Import the SBOM for an existing project/product once again',
|
||||||
|
required=False,
|
||||||
|
action='store_true',
|
||||||
|
default=False)
|
||||||
parser.add_argument('--verbose', '-V',
|
parser.add_argument('--verbose', '-V',
|
||||||
help='A lot of debug output',
|
help='A lot of debug output',
|
||||||
required=False,
|
required=False,
|
||||||
@ -105,6 +122,7 @@ projectVersion = args.version
|
|||||||
projectDescription = args.description
|
projectDescription = args.description
|
||||||
productType = args.type
|
productType = args.type
|
||||||
projectClassifier = args.classifier
|
projectClassifier = args.classifier
|
||||||
|
reImport = args.reimport
|
||||||
|
|
||||||
uploadSbomFlag = args.uploadsbom
|
uploadSbomFlag = args.uploadsbom
|
||||||
if uploadSbomFlag:
|
if uploadSbomFlag:
|
||||||
@ -113,6 +131,12 @@ if uploadSbomFlag:
|
|||||||
else:
|
else:
|
||||||
target = args.target
|
target = args.target
|
||||||
|
|
||||||
|
if minimalSbomFormat:
|
||||||
|
overwriteMetadata = args.overwritemetadata
|
||||||
|
|
||||||
|
if not overwriteMetadata and not (projectName and projectVersion and projectClassifier and projectDescription):
|
||||||
|
raise MyLocalException("If overwriteMetadata is not selected, projectName, projectVersion, projectClassifier and projectDescription must be set.")
|
||||||
|
|
||||||
VERBOSE = args.verbose
|
VERBOSE = args.verbose
|
||||||
|
|
||||||
|
|
||||||
@ -126,8 +150,13 @@ if uploadSbomFlag:
|
|||||||
logger.info("SBOM file read.")
|
logger.info("SBOM file read.")
|
||||||
if minimalSbomFormat:
|
if minimalSbomFormat:
|
||||||
logger.info("Start converting from minimal format into cyclonedx")
|
logger.info("Start converting from minimal format into cyclonedx")
|
||||||
sbom = minimalSbomFormatConverter(sbom, projectClassifier)
|
(sbom, nameFromMinimalSbom, versionFromMinimalSbom, classifierFromMinimalSbom, descriptionFromMinimalSbom) = minimalSbomFormatConverter(sbom, projectClassifier)
|
||||||
logger.info("Converted")
|
logger.info("Converted")
|
||||||
|
if overwriteMetadata:
|
||||||
|
projectName = nameFromMinimalSbom
|
||||||
|
projectVersion = versionFromMinimalSbom
|
||||||
|
projectClassifier = classifierFromMinimalSbom
|
||||||
|
projectDescription = descriptionFromMinimalSbom
|
||||||
logger.info("Done.")
|
logger.info("Done.")
|
||||||
else:
|
else:
|
||||||
# ------- generate SBOM ------------
|
# ------- generate SBOM ------------
|
||||||
@ -139,44 +168,46 @@ else:
|
|||||||
|
|
||||||
|
|
||||||
# ------- create product and engagement in DefectDojo -------
|
# ------- create product and engagement in DefectDojo -------
|
||||||
defectdojo_configuration = defectdojo_api.Configuration(
|
if not reImport:
|
||||||
host = DEFECTDOJO_URL
|
# in case of a reimport no modification on DefectDojo are required
|
||||||
)
|
defectdojo_configuration = defectdojo_api.Configuration(
|
||||||
defectdojo_configuration.api_key['tokenAuth'] = DEFECTDOJO_TOKEN
|
host = DEFECTDOJO_URL
|
||||||
defectdojo_configuration.api_key_prefix['tokenAuth'] = 'Token'
|
)
|
||||||
|
defectdojo_configuration.api_key['tokenAuth'] = DEFECTDOJO_TOKEN
|
||||||
|
defectdojo_configuration.api_key_prefix['tokenAuth'] = 'Token'
|
||||||
|
|
||||||
with defectdojo_api.ApiClient(defectdojo_configuration) as defectdojo_api_client:
|
with defectdojo_api.ApiClient(defectdojo_configuration) as defectdojo_api_client:
|
||||||
print("Create product in DefectDojo")
|
print("Create product in DefectDojo")
|
||||||
productName = f"{projectName}:{projectVersion}"
|
productName = f"{projectName}:{projectVersion}"
|
||||||
product_response = \
|
product_response = \
|
||||||
executeApiCall(
|
executeApiCall(
|
||||||
defectdojo_api_client,
|
defectdojo_api_client,
|
||||||
defectdojo_api.ProductsApi,
|
defectdojo_api.ProductsApi,
|
||||||
defectdojo_api.ProductsApi.products_create,
|
defectdojo_api.ProductsApi.products_create,
|
||||||
defectdojo_api.ProductRequest,
|
defectdojo_api.ProductRequest,
|
||||||
{ 'name': productName, 'description': projectDescription, 'prod_type': productType },
|
{ 'name': productName, 'description': projectDescription, 'prod_type': productType },
|
||||||
[]
|
[]
|
||||||
)
|
)
|
||||||
|
|
||||||
product_id = product_response.id
|
product_id = product_response.id
|
||||||
print(f"{product_id=}")
|
print(f"{product_id=}")
|
||||||
|
|
||||||
print("Create engagement in DefectDojo")
|
print("Create engagement in DefectDojo")
|
||||||
start_time = datetime.date.today()
|
start_time = datetime.date.today()
|
||||||
end_time = start_time + relativedelta(years=10)
|
end_time = start_time + relativedelta(years=10)
|
||||||
engagementName = f"{productName} DTrack Link"
|
engagementName = f"{productName} DTrack Link"
|
||||||
engagement_response = \
|
engagement_response = \
|
||||||
executeApiCall(
|
executeApiCall(
|
||||||
defectdojo_api_client,
|
defectdojo_api_client,
|
||||||
defectdojo_api.EngagementsApi,
|
defectdojo_api.EngagementsApi,
|
||||||
defectdojo_api.EngagementsApi.engagements_create,
|
defectdojo_api.EngagementsApi.engagements_create,
|
||||||
defectdojo_api.EngagementRequest,
|
defectdojo_api.EngagementRequest,
|
||||||
{ 'name': engagementName, 'target_start': start_time, 'target_end': end_time, 'status': 'In Progress', 'product': product_id },
|
{ 'name': engagementName, 'target_start': start_time, 'target_end': end_time, 'status': 'In Progress', 'product': product_id },
|
||||||
[]
|
[]
|
||||||
)
|
)
|
||||||
|
|
||||||
engagement_id = engagement_response.id
|
engagement_id = engagement_response.id
|
||||||
print(f"{engagement_id=}")
|
print(f"{engagement_id=}")
|
||||||
|
|
||||||
|
|
||||||
# ------- create project in DependencyTrack, connect project to engagement in DefectDojo, upload SBOM --------
|
# ------- create project in DependencyTrack, connect project to engagement in DefectDojo, upload SBOM --------
|
||||||
@ -187,36 +218,38 @@ dependencytrack_configuration.debug = False
|
|||||||
dependencytrack_configuration.api_key['ApiKeyAuth'] = DTRACK_TOKEN
|
dependencytrack_configuration.api_key['ApiKeyAuth'] = DTRACK_TOKEN
|
||||||
|
|
||||||
with dependencytrack_api.ApiClient(dependencytrack_configuration) as dependencytrack_api_client:
|
with dependencytrack_api.ApiClient(dependencytrack_configuration) as dependencytrack_api_client:
|
||||||
project_response = \
|
if not reImport:
|
||||||
executeApiCall(
|
# in case of a reimport it is not necessary to create the project
|
||||||
dependencytrack_api_client,
|
project_response = \
|
||||||
dependencytrack_api.ProjectApi,
|
executeApiCall(
|
||||||
dependencytrack_api.ProjectApi.create_project,
|
|
||||||
dependencytrack_api.Project,
|
|
||||||
{ 'name': projectName, 'version': projectVersion, 'classifier': projectClassifier, 'uuid': "", 'last_bom_import': 0 },
|
|
||||||
[]
|
|
||||||
)
|
|
||||||
|
|
||||||
project_uuid = project_response.uuid
|
|
||||||
print(f"{project_uuid=}")
|
|
||||||
|
|
||||||
properties = [
|
|
||||||
{ 'group_name': "integrations", 'property_name': "defectdojo.engagementId",
|
|
||||||
'property_value': str(engagement_id), 'property_type': "STRING" },
|
|
||||||
{ 'group_name': "integrations", 'property_name': "defectdojo.doNotReactivate",
|
|
||||||
'property_value': "true", 'property_type': "BOOLEAN" },
|
|
||||||
{ 'group_name': "integrations", 'property_name': "defectdojo.reimport",
|
|
||||||
'property_value': "true", 'property_type': "BOOLEAN" }
|
|
||||||
]
|
|
||||||
for property in properties:
|
|
||||||
executeApiCall(
|
|
||||||
dependencytrack_api_client,
|
dependencytrack_api_client,
|
||||||
dependencytrack_api.ProjectPropertyApi,
|
dependencytrack_api.ProjectApi,
|
||||||
dependencytrack_api.ProjectPropertyApi.create_property1,
|
dependencytrack_api.ProjectApi.create_project,
|
||||||
dependencytrack_api.ProjectProperty,
|
dependencytrack_api.Project,
|
||||||
property,
|
{ 'name': projectName, 'version': projectVersion, 'classifier': projectClassifier, 'uuid': "", 'last_bom_import': 0 },
|
||||||
[ project_uuid ]
|
[]
|
||||||
)
|
)
|
||||||
|
|
||||||
|
project_uuid = project_response.uuid
|
||||||
|
print(f"{project_uuid=}")
|
||||||
|
|
||||||
|
properties = [
|
||||||
|
{ 'group_name': "integrations", 'property_name': "defectdojo.engagementId",
|
||||||
|
'property_value': str(engagement_id), 'property_type': "STRING" },
|
||||||
|
{ 'group_name': "integrations", 'property_name': "defectdojo.doNotReactivate",
|
||||||
|
'property_value': "true", 'property_type': "BOOLEAN" },
|
||||||
|
{ 'group_name': "integrations", 'property_name': "defectdojo.reimport",
|
||||||
|
'property_value': "true", 'property_type': "BOOLEAN" }
|
||||||
|
]
|
||||||
|
for property in properties:
|
||||||
|
executeApiCall(
|
||||||
|
dependencytrack_api_client,
|
||||||
|
dependencytrack_api.ProjectPropertyApi,
|
||||||
|
dependencytrack_api.ProjectPropertyApi.create_property1,
|
||||||
|
dependencytrack_api.ProjectProperty,
|
||||||
|
property,
|
||||||
|
[ project_uuid ]
|
||||||
|
)
|
||||||
|
|
||||||
bom_response = \
|
bom_response = \
|
||||||
executeApiCall(
|
executeApiCall(
|
||||||
|
Reference in New Issue
Block a user